GHSA-jr65-gpj5-cw74

Source
https://github.com/advisories/GHSA-jr65-gpj5-cw74
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-jr65-gpj5-cw74/GHSA-jr65-gpj5-cw74.json
Aliases
Published
2022-12-28T03:30:28Z
Modified
2023-11-08T04:09:39.845988Z
Details

go-resolver's DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.

References

Affected packages

Go / github.com/peterzen/goresolver

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Last affected
1.0.2